Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
An examiner, an internal auditor or an acquirer asks the same question: show me everything you hold on this third party, and show me how you decided. Coverbase answers it from the vendor record itself, without anyone assembling a folder by hand.

The full vendor report

From a vendor’s page, Export report builds a single branded PDF of the whole relationship. Choose the depth and the sections, and Coverbase builds it in the background and notifies you when it is ready.

Executive summary

Risk posture, profile and the latest assessment outcome. A few pages, for a committee pack.

Standard

Adds services, assessments, findings, contracts, obligations and documents.

Full

Everything, including the bill of materials, notes, and the complete audit trail.
A full vendor report carries, in one document: The report carries your brand: your logo and accent color in the running header, the vendor’s mark on the masthead, and your third-party contact address in the footer. It is a document you can hand to a regulator without reformatting it.
The same three-tier export exists at service level, for programs that diligence per service rather than per legal entity, and at assessment level for a single review cycle.

Everything else in the package

The underlying documents, as an archive

Select the vendor’s documents and download them as a single .zip: SOC 2 reports, certificates, policies, questionnaire attachments, signed contracts, and anything else collected. The archive builds in the background and lands in your documents when it is ready. Bulk document export is org-scoped and gated on an export permission, so it is deliberately not something an assigned-only reader can trigger.
A full assessment PDF adds per-control evidence: the evaluation, the citation, the evidence snippet images, the reviews, follow-ups, notes and the activity log for that assessment. This is the layer that shows how a control was judged, not just what the judgment was. See Reporting overview.
Upload your firm’s house report as a .docx with placeholders, and Coverbase fills it per assessment from live data, including AI-answered narrative sections. Your layout, your headings, your language. See Assessment report templates.
Org-level .xlsx exports cover many assessments at once: a filtered list of assessments, or every assessment result within a date range, for the population testing an examiner asks for rather than one file at a time.
The Export API returns vendors, services, assessments, evaluations, controls, findings, obligations and contracts as JSON, filtered and paginated, so a package can be assembled on a schedule into your GRC platform, warehouse or regulator submission pipeline.
GET /v1/system_audit_log returns the organization-wide record of every action, including public-API calls and AI assistant tool calls, filterable and exportable. See Audit trails.

Assembling an examination package

1

Pick the population

Filter the vendor list to the population in scope: critical activities, a business line, a tier, a data classification, a jurisdiction, or a custom field of your own. Save it as a view so the same population reproduces next time.
2

Export the portfolio evidence

Run the bulk assessment .xlsx for the date range under examination. This is the sampling frame.
3

Export the full file for each sampled third party

For each vendor the examiner picks, export the Full vendor report and the document archive. Between them they carry the profile, the diligence, the decisions, the paper, the monitoring, and the audit trail.
4

Add the program-level evidence

Your control sets, your workflow definitions, your roles and their permission matrices, and the regulatory alignment mapping, which shows what the program was designed against.
Run this once before you need it. The week an examination opens is a bad time to find out what the package does and does not contain.

Reporting overview

Every reporting surface and which one to use.

Regulatory alignment

What the package is evidencing, mapped to the guidance.

Export API

The structured, programmatic path.

Audit trails

The record behind every decision in the package.